From: shibayashi Date: Fri, 28 Dec 2018 20:09:48 +0000 (+0100) Subject: Security/Drops the sysadmin privilege from the daemon X-Git-Url: https://git.squeep.com/?a=commitdiff_plain;h=64035201b56ee78dc937dfa675e610c03850dcad;p=akkoma Security/Drops the sysadmin privilege from the daemon --- diff --git a/installation/pleroma.service b/installation/pleroma.service index 6955e5cc6..f1ed56cb3 100644 --- a/installation/pleroma.service +++ b/installation/pleroma.service @@ -21,6 +21,8 @@ ProtectSystem=full PrivateDevices=false ; Ensures that the service process and all its children can never gain new privileges through execve(). NoNewPrivileges=true +; Drops the sysadmin capability from the daemon. +CapabilityBoundingSet=~CAP_SYS_ADMIN [Install] WantedBy=multi-user.target